www.rapid7.com 7/30/2026, 1:01:11 PM · external

Patch now: critical VMware vCenter remote code flaws

Patch now: critical VMware vCenter remote code flaws
Developing story vulnerability 5 articles tracked
Broadcom patches multiple critical VMware vulnerabilities
CyberSIXT Evidence Panel
Primary Source support.broadcom.com
CISA KEV Not in KEV
Patch Patch Status Unknown

ON July 29, 2026, Broadcom disclosed two critical vulnerabilities in VMware vCenter Server, CVE-2026-59309 and CVE-2026-59310, both with a CVSSv3.1 score of 9.8. CVE-2026-59309 represents an authentication bypass that allows unauthorized access to the vCenter management plane, while CVE-2026-59310 involves a directory traversal vulnerability that enables remote code execution. Exploitation does not require prior authentication, but attackers must have network access.

There is currently no known proof-of-concept for exploitation, making immediate patching essential as exploitation in the wild could occur. Organizations are urged to apply the updates suggested in Broadcom's security advisory promptly. Rapid7 customers can assess their exposure using specific vulnerability checks.

View Primary Source Via www.rapid7.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline